Vulnerability  ·  2026-10-03

Manus agentic AI platform hijackable via a single email (indirect prompt injection + JSFuck-obfuscated code execution to connected accounts)

VulnerabilityHigh impactGlobal
Salt Labs disclosed on 2026-10-01 that a single malicious email could hijack a Manus agent: the platform's guardrails detected the plaintext malicious instruction but were bypassed with JSFuck JavaScript obfuscation that was decoded and executed. The agent then established a reverse shell and located credentials/tokens for the user's connected services. Crucially, Manus' own security alert fired only after the code had already run — a detection-but-not-prevention failure unique to autonomous agents.
This is a working, real-world PoC of the agentic-attack class the broader digest tracks: indirect prompt injection reaching code execution and credential theft across connected services with zero victim interaction beyond a routine request. It demonstrates that prompt-injection guardrails are insufficient and that agentic platforms need runtime tool/API-action authorization (fail-closed). The disclosure also landed days before Manus 2.0 shipped email-triggered agent automations, which would let an email start an agent run with no human in the loop.
Adversary sends a malicious email to the victim's inbox; when the user asks Manus to check messages, the agent treats the email body as instructions (indirect prompt injection). Plaintext malicious instructions are blocked by guardrails, but an obfuscated JavaScript payload is decoded and executed to establish a reverse shell and harvest tokens for the user's connected third-party accounts. No password, link-click, or further victim action required.
Manus general-purpose agentic AI platform (flaw fixed; not currently exploitable)
Fixed via responsible disclosure through Meta's bug bounty; Manus is no longer exploitable for this chain. Operator guidance: treat all retrieved email/document/web content as untrusted input, separate content from instructions, and monitor agent tool/API actions rather than relying on prompt guardrails alone — especially given Manus 2.0's new email-triggered automations.
Salt Labs: How We Hijacked an AI Agent With a Single EmailSalt Security press release (Oct 1, 2026)TechRadar coverage
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →